Your Privacy and the Security of Your Personal Information is Very Important to Us

CRYSTAL ROCK STAR and its affiliates, value our customers and visitors to our Websites and respect your concerns about the privacy of your personal information and data security. Our Privacy and Security Policy (the "Privacy Policy") is intended to protect your privacy and provide you with a safe and secure experience in fashion, style and shopping. This Privacy Policy applies to our Websites hosted in the United States and to our fashion marketing and sales activities. This Privacy Policy protects consumers providing information through our Websites and is not designed to protect business information. By using our Websites and providing information to us, you consent to the collection and use of your personal information. In addition to reviewing our Privacy Policy, you should also read our Terms of Use for our Website. Your use of our Website constitutes your agreement to its terms and conditions.

Our Privacy Policy Will Change Over Time

Because we continue to develop our Website and take advantage of technologies to improve the services we provide, our policies will change over time. We encourage you to refer to this Privacy Policy from time to time to stay abreast of our most current privacy policy practices. Your continued access and use of our Websites will constitute your acceptance of any changes or revisions to our Privacy Policy.

The Type of Information our Websites and Stores Collect About You

CRYSTAL ROCK STAR collects information that you provide to us or that we learn about you from your use of our Websites. We receive and store information you enter on our Websites or give to us in any other way. For example, you may provide information to us when you register with our Website, sign-in, search, add items to your shopping cart, pay for an item, participate in a survey, contest or promotion, apply for a job, request to receive our marketing materials, or communicate with CRYSTAL ROCK STAR's customer service. As a result of those actions, you might supply us with such information as your name, address, phone number, email address, payment card information, and personal shopping and product preferences. In applying for a job with us, you may provide to us your name, address, phone number, email address, previous work experience, references and other personal information about your background and experience.

We also automatically receive and store certain types of information whenever you visit our Website. We might also receive information about you from other sources, such as in providing you special offers that we think will be of interest, and we may add that information to our account information.

How CRYSTAL ROCK STAR Uses Information About You

We use information we have collected about you to provide you with the very best shopping experience. We do not sell your personal information to third parties for any reason. We do not disclose your personal information to unaffiliated third parties, or to our affiliates, who may want to offer you their own products and services unless you have requested or authorized us to do so.

We may share your personal information with third parties or affiliates of CRYSTAL ROCK STAR where it is necessary for us to complete a transaction you authorized or perform some other activity you have asked us to do.

We may share your personal information with third parties or affiliates of CRYSTAL ROCK STAR with whom we have contracted to perform services on our behalf to allow the business to function. All companies that act on our behalf are contractually obligated to keep the personal information we provide to them confidential and to use the personal information we share only to provide the services we ask them to perform.

We may disclose personal information about our customers as permitted or required by law, such as in connection with a subpoena or similar legal process, or in connection with a merger, acquisition, as discussed further below. We may disclose information about you to protect against fraud and other crimes and to enforce our contracts with you.

We try to provide you with the information you need to make informed reasonable choices with respect to how our Website uses or shares your information. CRYSTAL ROCK STAR collects and uses personal information from you in several ways:

  • Website usage. CRYSTAL ROCK STAR’s authorized service providers may observe activities, preferences and transactional data (such as your IP address, browser type and operating system) relating to your use of our Website. We may use this collected or logged information in order to provide better service, to facilitate our customers' use of the website, to track usage of the website, and to address security hazards. CRYSTAL ROCK STAR, or one of CRYSTAL ROCK STAR’s authorized service providers, may use this information to track aggregate traffic patterns throughout our Website for CRYSTAL ROCK STAR’s internal analysis.

  • Online Transactions. We collect information about you when you shop on our website. You may visit our site without registering, but if you wish to add merchandise to your shopping cart, or use other special features offered on our site, you will need to provide us with certain information, including your name, address, phone number and email address, to open an account with us. We will assist you in creating a user id and a password to protect your account information.


Our Security Practices

Our internal data security policies restrict access to customers' personal information to authorized employees. Authorized employees may use our customers' personal information for CRYSTAL ROCK STAR business purposes only. Our employees are bound by CRYSTAL ROCK STAR policies that require them to maintain the confidentiality of our customers' personal information. Employees who violate these requirements are subject to disciplinary action, up to and including termination.

We maintain physical, electronic, and procedural safeguards that are designed to guard our customers' personal information. For example, for the security of your online visit to our Website, we may make use of firewall barriers, encryption techniques and/or authentication procedures. Unfortunately, no data transmission over the Internet can be guaranteed to be absolutely secure. As a result, while we strive to protect your personal information, CRYSTAL ROCK STAR cannot ensure or warrant the security of any information you transmit to us, and you do so at your own risk. In the event of a breach of the confidentiality or security of your personal information, we will notify you as necessary and to the extent possible so you can take appropriate protective steps. Unless you indicate otherwise, we may notify you under such circumstances using the email address you provided to us when you registered with our Website.

What are Cookies and How Does our Website Use Them?

We may use "cookies" to collect or log certain information. A cookie is a small piece of information that a website stores on a personal computer and which it can later retrieve. We may use cookies for some administrative purposes, for example, to store our customers' preferences for certain kinds of products. The cookies will not contain information that will enable anyone to contact our customers via telephone, email, or any other means. If our customers are uncomfortable with the use of cookie technology, they can set their browsers to refuse cookies. Certain of our services, however, could be dependent on cookies and our customers may disable those services by refusing cookies.

Links to Third Party Sites and Websites Containing our Websites Branding

Our Websites may contain links to third party sites. Please be aware, however, that CRYSTAL ROCK STAR is not responsible for and cannot control the privacy policies of these other sites or their practices. We encourage you to read the privacy policies for these other sites, as they may differ from ours. This Privacy Policy applies solely to personal information collected by CRYSTAL ROCK STAR.

Contact Preferences and Accessing Your Personal Information

You have choices when it comes to how CRYSTAL ROCK STAR uses your personal information. When you register online with our Website, you can choose not to receive information about merchandise, services and special promotional offers from us by direct mail and/or email. If you elect not to receive such product marketing information by direct mail or email, CRYSTAL ROCK STAR may continue to contact you as necessary to service your account and process your transactions. You can change your preferences and request to opt out by leaving a message on the Contact page of our website.

Keeping your account information accurate and up to date is very important so we can provide you with excellent service. If your account information is incomplete, inaccurate or not current, please login to your Account on our Website to correct or update your account information online, or you may contact sent us a message on our Contact page of our website.

Mergers, Acquisitions, Status Change

If CRYSTAL ROCK STAR should ever change it's business standing or merge with another company, or if CRYSTAL ROCK STAR should decide to buy another business, or sell or reorganize part or all of CRYSTAL ROCK STAR’s business, CRYSTAL ROCK STAR may be required to disclose your personal information to prospective or actual purchasers and other parties. It is CRYSTAL ROCK STAR’s practice to obtain appropriate protections for information disclosed in these types of transactions. CRYSTAL ROCK STAR cannot, however, guarantee that CRYSTAL ROCK STAR’s Privacy Policy will remain unchanged if CRYSTAL ROCK STAR is sold or merges with another company.

What else should I know about my privacy?

You should be careful to maintain the secrecy of your passwords and/or account information and be responsible about protecting your personal information and identity whenever you are online.

*********************

Additional Info for GDPR

1) Information Collected

To fulfill your order, you must provide certain information, such as your name, email, postal address, payment info, and the details of the product in your order. You may also choose to provide additional personal information (for a custom order, for example), if you contact the shop directly.

2) Why This Information Is Collected and How Its Used

The shop relies on legal bases to collect, use, and share your information, including:

- as needed to provide service, such as when I use your information to fulfill your order, to settle disputes, or to provide customer support;
- when you have provided your affirmative consent, which you may revoke at any time, such as by signing up for the shop's email mailing list;
- if necessary to comply with a legal obligation or court order or in connection with a legal claim, such as retaining information about your purchases if required by tax law; and
- as necessary for the purpose of legitimate interests, if those legitimate interests are not overridden by your rights or interests, such as 1) providing and improving services. Crystal Rock Star uses your information to provide the services you requested and in legitimate interest to improve services

3) Information Sharing and Disclosure

Information about customers is important to Crystal Rock Star. Your personal information is only shared for very limited reasons and in limited circumstances, as follows:

- Shopify. We share information with Shopify as necessary to provide you services and comply with obligations.
- Service providers. We engage certain trusted third parties to perform functions and provide services to my shop, such as delivery companies. We share your personal info with these third parties, but only to the extent necessary to perform these services.
- Business transfers. If Crystal Rock Star sells or merges its business, we may disclose your information as part of that transaction, only to the extent permitted by law.
- Compliance with laws. We may collect, use, retain, and share your information if we have a good faith belief that it is reasonably necessary to: (a) respond to legal process or to government requests; (b) enforce agreements, terms and policies; (c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or (d) protect the rights, property, and safety of customers, or others.

4) Data Retention

We retain your personal information only for as long as necessary to provide you with services and as described in the Privacy Policy. However, we may also be required to retain this information to comply with legal and regulatory obligations, to resolve disputes, and to enforce my agreements. We generally keep your data for the following time period: 4 years.

5) Transfers of Personal Information Outside the EU

We may store and process your information through third-party hosting services in the US and other jurisdictions. As a result, we may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction. If we are deemed to transfer information about you outside of the EU, we rely on Privacy Shield as the legal basis for the transfer, as Google Cloud is Privacy Shield certified.

6) Your Rights

If you reside in certain territories, including the EU, you have a number of rights in relation to your personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. We describe these rights below:

- Access. You may have the right to access and receive a copy of the personal information we hold about you by contacting us using on the contact page of the Crystal Rock Star shop.
- Change, restrict, delete. You may also have rights to change, restrict use of, or delete your personal information. Absent exceptional circumstances (like where we are required to store data for legal reasons) we will generally delete your personal information upon request.
- Object. You can object to (i) processing of some of your information based on legitimate interests and (ii) receiving marketing messages from Crystal Rock Star after providing your express consent to receive them. In such cases, we will delete your personal information unless we have compelling and legitimate grounds to continue using that information or if it is needed for legal reasons.
- Complain. If you reside in the EU and wish to raise a concern about the use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.

For purposes of EU data protection law, Crystal Rock Star and Shopify, is the data controller of your personal information via any transactions made via https://crystalrockstar.com. If you have any questions or concerns, you may send a direct message on the Crystal Rock Star shop's Contact Page. 

Privacy statement dated 5/16/2018.